Security Research · 6 September 2026

Investigating Crusader Worker 1.0: 91 IP Addresses, 20 Google Cloud Regions, and the Footprints of a Distributed Internet Scanner

A technical investigation based on 91 source IPs, 674 Fail2Ban matches, first-party telemetry, and independent public observations.

Attribution warning: Google LLC / Google Cloud network ownership does not mean Google operates Crusader. Infrastructure ownership and operator identity are different facts.

Executive Summary

ProfesyonelWeb observed a distributed scanning campaign using crusader-worker/1.0. At the 6 September 2026 snapshot, the dedicated pweb-crusader-worker-v1 jail recorded 674 matches and 91 banned source IPs. The first 90 addresses matched Google's official cloud.json customer-resource prefixes across 20 Google Cloud scopes. The 91st IP, 34.34.191.23, was captured later during the same live campaign and WHOIS identified Google LLC. We do not claim an independently verified region/scope for that 91st address in this publication.

What Is Crusader Worker 1.0?

The most defensible behavioral description is a distributed web exposure and vulnerability discovery scanner. Its operator and official project ownership remain unknown. We therefore do not attribute it to Google, Censys, Shodan, or any other organization without evidence.

Where does the name “Crusader Worker” come from? We did not assign this name as researchers. The observed HTTP clients identify themselves literally with User-Agent: crusader-worker/1.0. Current evidence does not establish whether this is the scanner's actual product/project name, an operator-selected worker label, or simply a scanning signature.

Probe Family One: Secrets and Framework Exposure

Repeated paths include /.env, /env, WordPress configuration remnants, Laravel logs and Ignition endpoints, and Spring Boot Actuator paths. These are common places where secrets, backups, or diagnostic surfaces may be accidentally exposed.

Probe Family Two: Git Repository Exposure

Independent public logs also show broad /.git/config discovery across common deployment roots such as /api, /backend, /src, /app, /site, /wordpress, /htdocs, /var/www, /www, /public, and /html.

The Curious /crusader-404-probe

This custom path is one of the campaign's strongest behavioral identifiers. Its behavior is consistent with a control request used to learn a site's normal 404 or soft-404 response, but that remains a technical inference rather than a documented operator statement.

Burst Scanning

Multiple workers fired many distinct probes within the same second. That strongly supports automated parallel or asynchronous execution. A centralized controller, queue, or serverless scheduler would be plausible architecture, but is not proven.

Google Cloud Distribution — First 90 IPs

Official Google Cloud prefix matching returned 90/90 matches for the first cohort. 62 addresses were in US scopes (68.9%); 28 were outside the US.

Google Cloud scopeIP count
us-east121
us-central118
us-east411
us-west15
europe-west34
us-west34
europe-west43
us-west23
asia-northeast33
europe-west13
europe-southwest13
asia-southeast23
southamerica-east12
asia-south11
asia-southeast11
europe-west61
europe-north11
northamerica-northeast11
asia-east21
australia-southeast11

Network Fingerprints

Two independent Crusader observations on ELLIO shared the same User-Agent, overlapping probe vocabulary, and identical TCP/MuonFP value 65320:2-4-8-1-3:1420:10. One of them, 35.236.75.211, also exposed JA4 t13i1010h1_61a7ad8aa9b6_3a8073edd8ef. We do not generalize that JA4 to the full fleet.

Evidence / Inference / Unknown

ESTABLISHED

91 source IPs in the Crusader jail; consistent crusader-worker/1.0 User-Agent; repeated sensitive-path probes; first 90 matched official Google Cloud ranges.

STRONG BEHAVIORAL FINDING

Same-second bursts, repeated task sequences across workers, and the custom 404 probe are consistent with coordinated automation.

UNKNOWN

Operator identity, official project ownership, controller architecture, and whether the full fleet shares one TLS fingerprint.

ProfesyonelWeb First-Party IOC Dataset — 6 September 2026

The following 91 addresses were captured by the dedicated pweb-crusader-worker-v1 jail in our infrastructure. They are network IOCs, not identities of people or organizations.

IOC lifecycle warning: These addresses are observational IOCs associated with crusader-worker/1.0 in the 6 September 2026 research snapshot. IP addresses in cloud infrastructure may be reassigned over time; this dataset should therefore not be treated as a permanent or indefinite blocklist. Future blocking decisions should be revalidated against current User-Agent data, request behavior, targeted paths, timing correlation, and other telemetry.
Source IPSignatureSource
34.73.126.230crusader-worker/1.0ProfesyonelWeb first-party telemetry
34.159.204.144crusader-worker/1.0ProfesyonelWeb first-party telemetry
34.26.203.248crusader-worker/1.0ProfesyonelWeb first-party telemetry
35.188.94.210crusader-worker/1.0ProfesyonelWeb first-party telemetry
34.85.179.64crusader-worker/1.0ProfesyonelWeb first-party telemetry
34.59.21.111crusader-worker/1.0ProfesyonelWeb first-party telemetry
104.198.56.247crusader-worker/1.0ProfesyonelWeb first-party telemetry
34.24.59.51crusader-worker/1.0ProfesyonelWeb first-party telemetry
35.188.7.174crusader-worker/1.0ProfesyonelWeb first-party telemetry
34.171.230.203crusader-worker/1.0ProfesyonelWeb first-party telemetry
34.70.161.3crusader-worker/1.0ProfesyonelWeb first-party telemetry
34.63.245.57crusader-worker/1.0ProfesyonelWeb first-party telemetry
35.237.69.213crusader-worker/1.0ProfesyonelWeb first-party telemetry
35.185.73.65crusader-worker/1.0ProfesyonelWeb first-party telemetry
35.245.146.204crusader-worker/1.0ProfesyonelWeb first-party telemetry
8.34.219.127crusader-worker/1.0ProfesyonelWeb first-party telemetry
34.12.8.212crusader-worker/1.0ProfesyonelWeb first-party telemetry
136.114.140.138crusader-worker/1.0ProfesyonelWeb first-party telemetry
34.138.81.27crusader-worker/1.0ProfesyonelWeb first-party telemetry
34.42.49.156crusader-worker/1.0ProfesyonelWeb first-party telemetry
34.24.165.179crusader-worker/1.0ProfesyonelWeb first-party telemetry
34.20.225.161crusader-worker/1.0ProfesyonelWeb first-party telemetry
34.47.99.51crusader-worker/1.0ProfesyonelWeb first-party telemetry
34.182.153.4crusader-worker/1.0ProfesyonelWeb first-party telemetry
136.70.92.192crusader-worker/1.0ProfesyonelWeb first-party telemetry
136.70.64.27crusader-worker/1.0ProfesyonelWeb first-party telemetry
34.148.223.6crusader-worker/1.0ProfesyonelWeb first-party telemetry
34.20.168.239crusader-worker/1.0ProfesyonelWeb first-party telemetry
8.231.78.19crusader-worker/1.0ProfesyonelWeb first-party telemetry
34.23.241.158crusader-worker/1.0ProfesyonelWeb first-party telemetry
8.234.239.54crusader-worker/1.0ProfesyonelWeb first-party telemetry
34.48.118.123crusader-worker/1.0ProfesyonelWeb first-party telemetry
35.243.136.237crusader-worker/1.0ProfesyonelWeb first-party telemetry
34.86.81.18crusader-worker/1.0ProfesyonelWeb first-party telemetry
34.138.148.25crusader-worker/1.0ProfesyonelWeb first-party telemetry
34.79.114.166crusader-worker/1.0ProfesyonelWeb first-party telemetry
8.228.241.247crusader-worker/1.0ProfesyonelWeb first-party telemetry
35.230.115.27crusader-worker/1.0ProfesyonelWeb first-party telemetry
136.85.72.46crusader-worker/1.0ProfesyonelWeb first-party telemetry
34.65.122.177crusader-worker/1.0ProfesyonelWeb first-party telemetry
35.196.69.53crusader-worker/1.0ProfesyonelWeb first-party telemetry
34.88.75.40crusader-worker/1.0ProfesyonelWeb first-party telemetry
34.44.113.134crusader-worker/1.0ProfesyonelWeb first-party telemetry
34.106.72.61crusader-worker/1.0ProfesyonelWeb first-party telemetry
35.229.18.104crusader-worker/1.0ProfesyonelWeb first-party telemetry
34.185.231.221crusader-worker/1.0ProfesyonelWeb first-party telemetry
34.75.27.14crusader-worker/1.0ProfesyonelWeb first-party telemetry
34.26.183.3crusader-worker/1.0ProfesyonelWeb first-party telemetry
34.41.241.201crusader-worker/1.0ProfesyonelWeb first-party telemetry
136.118.193.212crusader-worker/1.0ProfesyonelWeb first-party telemetry
104.196.1.67crusader-worker/1.0ProfesyonelWeb first-party telemetry
35.234.122.138crusader-worker/1.0ProfesyonelWeb first-party telemetry
34.74.13.50crusader-worker/1.0ProfesyonelWeb first-party telemetry
34.118.173.99crusader-worker/1.0ProfesyonelWeb first-party telemetry
34.175.253.53crusader-worker/1.0ProfesyonelWeb first-party telemetry
34.52.218.172crusader-worker/1.0ProfesyonelWeb first-party telemetry
34.175.91.18crusader-worker/1.0ProfesyonelWeb first-party telemetry
34.44.189.55crusader-worker/1.0ProfesyonelWeb first-party telemetry
35.203.143.148crusader-worker/1.0ProfesyonelWeb first-party telemetry
34.90.212.195crusader-worker/1.0ProfesyonelWeb first-party telemetry
35.220.159.6crusader-worker/1.0ProfesyonelWeb first-party telemetry
34.39.214.130crusader-worker/1.0ProfesyonelWeb first-party telemetry
34.32.163.117crusader-worker/1.0ProfesyonelWeb first-party telemetry
34.171.193.51crusader-worker/1.0ProfesyonelWeb first-party telemetry
34.106.38.212crusader-worker/1.0ProfesyonelWeb first-party telemetry
35.188.33.158crusader-worker/1.0ProfesyonelWeb first-party telemetry
34.50.105.82crusader-worker/1.0ProfesyonelWeb first-party telemetry
34.55.254.111crusader-worker/1.0ProfesyonelWeb first-party telemetry
34.186.144.127crusader-worker/1.0ProfesyonelWeb first-party telemetry
34.175.183.75crusader-worker/1.0ProfesyonelWeb first-party telemetry
34.148.10.27crusader-worker/1.0ProfesyonelWeb first-party telemetry
34.101.232.28crusader-worker/1.0ProfesyonelWeb first-party telemetry
8.234.161.192crusader-worker/1.0ProfesyonelWeb first-party telemetry
104.196.17.155crusader-worker/1.0ProfesyonelWeb first-party telemetry
35.244.69.211crusader-worker/1.0ProfesyonelWeb first-party telemetry
34.64.99.234crusader-worker/1.0ProfesyonelWeb first-party telemetry
35.255.237.118crusader-worker/1.0ProfesyonelWeb first-party telemetry
34.106.91.172crusader-worker/1.0ProfesyonelWeb first-party telemetry
34.14.111.10crusader-worker/1.0ProfesyonelWeb first-party telemetry
34.185.239.175crusader-worker/1.0ProfesyonelWeb first-party telemetry
34.47.82.185crusader-worker/1.0ProfesyonelWeb first-party telemetry
34.128.82.22crusader-worker/1.0ProfesyonelWeb first-party telemetry
34.95.228.141crusader-worker/1.0ProfesyonelWeb first-party telemetry
34.11.183.85crusader-worker/1.0ProfesyonelWeb first-party telemetry
34.74.93.223crusader-worker/1.0ProfesyonelWeb first-party telemetry
35.190.179.122crusader-worker/1.0ProfesyonelWeb first-party telemetry
34.45.252.177crusader-worker/1.0ProfesyonelWeb first-party telemetry
34.48.88.185crusader-worker/1.0ProfesyonelWeb first-party telemetry
34.145.72.43crusader-worker/1.0ProfesyonelWeb first-party telemetry
34.21.67.240crusader-worker/1.0ProfesyonelWeb first-party telemetry
34.34.191.23crusader-worker/1.0ProfesyonelWeb first-party telemetry

Defending Against Similar Scanners

The primary defense is to ensure a scanner has nothing valuable to retrieve: secrets, backup configuration files, repository metadata, debug endpoints and actuator endpoints should not be publicly accessible. Fail2Ban, Nginx deny rules and WAF controls are secondary layers. Behind Cloudflare, origin-only iptables rules may not be sufficient; a real-client-IP-aware Nginx or WAF layer is important.

Independent Public Observations

Conclusion

Crusader Worker 1.0 behaves like a standardized, automated and distributed web exposure/vulnerability discovery scanner. We do not know who operates it. This research will be updated if new probe families, new fingerprints, or credible attribution evidence emerge.


Research note: IP count is not VM count. Google Cloud network space does not imply Google attribution. HTTP 200 alone does not prove a sensitive resource is exposed because soft-404 and fallback routing must be considered.